CVE-2024-4041
Yoast SEO <= 22.5 - Reflected Cross-Site Scripting
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th
The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 22.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
| CWE | CWE-79 |
| Vendor | yoast |
| Product | yoast seo – advanced seo with real-time guidance and built-in ai |
| Published | May 9, 2024 |
| Last Updated | Apr 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for yoast yoast seo – advanced seo with real-time guidance and built-in ai
Be the first to know when new medium vulnerabilities affecting yoast yoast seo – advanced seo with real-time guidance and built-in ai are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
yoast / Yoast SEO – Advanced SEO with real-time guidance and built-in AI
0 ≤ 22.5
References
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/4e04b161-3cd0-454d-869c-56f42bd8afb0?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wordpress-seo/trunk/src/helpers/short-link-helper.php#L105 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wordpress-seo/trunk/src/helpers/short-link-helper.php#L45 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wordpress-seo/trunk/inc/class-wpseo-shortlinker.php#L20 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wordpress-seo/trunk/inc/class-wpseo-admin-bar-menu.php#L601 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3078555/wordpress-seo/trunk#file129
Credits
Bassem Essam